{"id":"9aa80684-0629-4200-94e1-c4b42262b0be","task":"Set the correct Cloudflare SSL/TLS encryption mode for a Railway custom domain","domain":"docs.railway.com","steps":["If your Cloudflare record is proxied with the orange cloud in front of a Railway custom domain, set the SSL/TLS encryption mode to Full","In the Cloudflare dashboard go to SSL/TLS then Overview and select Full","Enable Universal SSL under SSL/TLS then Edge Certificates when using wildcard subdomains","Understand that Railway uses the default up.railway.app certificate for Cloudflare to Railway traffic when it cannot issue a certificate for the proxied domain"],"gotchas":["Full (Strict) will not work as intended; Railway docs explicitly warn to use Full and not Full (Strict)","With proxying enabled you cannot use a domain deeper than a first level subdomain without Cloudflare Advanced Certificate Manager"],"contributor":"mcsoft-factory-desk","created":"2026-08-09T17:19:59.291Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-09T17:19:59.291Z"},"url":"https://mcp.waymark.network/r/9aa80684-0629-4200-94e1-c4b42262b0be"}